What happens in a SOC 2 examination, and how long readiness takes

SOC 2 runs in phases: scoping, a gap assessment, remediation, an optional Type 1 report, an observation period in which your controls must operate and leave evidence, Type 2 fieldwork by a CPA firm, and the report. Most of the calendar is readiness and observation, which you control; the length depends on your starting point and the period you agree with the firm, so treat any fixed promise with suspicion.

What are the phases of SOC 2, in order?

PhaseWhat happensWho does it
ScopingChoose the system, the services and the trust services categories: security, plus any of availability, processing integrity, confidentiality and privacy your customers needYou, with readiness help
Gap assessmentCompare what you do today with the criteria and list what is missingYou, with readiness help
RemediationWrite the policies, put the controls in place, and start keeping evidence as a habitYou
Type 1 (optional)The CPA firm reports on the design of controls at a point in timeCPA firm
Observation periodControls operate and produce evidence across an agreed periodYou
Type 2 fieldworkThe CPA firm tests whether controls operated effectively across that periodCPA firm
ReportDelivered to you, to share with customers under non-disclosureCPA firm

Only a licensed CPA firm can perform a SOC 2 examination and sign the report. A readiness consultancy prepares you for it, and cannot be the firm that examines the same work. The professional standards come from the AICPA, which describes SOC as “a suite of service offerings CPAs may provide”. A Type 2 report contains management’s assertion, your description of the system, the CPA firm’s opinion, and the tests of controls with their results; as of September 2026, the AICPA publishes an illustrative Type 2 report.

Should you start with a Type 1 report?

Often, when a customer needs something soon. A Type 1 report covers the design of your controls at a point in time; it does not show they operated over a period, which is what a Type 2 report adds and what most enterprise buyers ask for in the end.

A Type 1 is useful when a deal is waiting and your controls are designed but young. It is not useful as a substitute: buyers who ask for SOC 2 usually mean a Type 2, and a Type 1 on its own mostly buys time. The two reports are compared in SOC 2 Type 1 vs Type 2. The distinction between a SOC 2 report and an ISO/IEC 27001 certificate is covered in SOC 2 vs ISO 27001.

What decides how long readiness takes?

How long SOC 2 takes depends on where you start, how much you have to fix, and the observation period you agree with the CPA firm. Anyone quoting a duration before seeing your gaps is guessing; a gap assessment is what turns the question into a plan. The drivers, roughly in order of weight:

  • Starting maturity. Access reviews, change control, onboarding and offboarding, logging and vendor review either exist and leave records, or they do not.
  • Scope. Every extra category, service or system adds controls to design and evidence to keep.
  • Remediation capacity. The work lands on engineers who also ship product. Name owners and protect their time.
  • The observation period. It is agreed with the CPA firm and shaped by what your customers will accept. It cannot be shortened by working harder.
  • The CPA firm’s calendar. Engage one early; fieldwork slots fill up.

Which SOC 2 myths cost time?

“The platform does it for us.” No. A compliance platform can organize evidence and automate its collection, but it cannot operate your controls or examine them. The controls have to run, and a CPA firm has to test them. The AICPA’s Journal of Accountancy has itself published warnings (February 2026) about quick-turn SOC engagements.

“We will fix things during the observation period.” Controls that start halfway through the period have not operated across it, and that shows in the report. Finish remediation first.

“Policies are the hard part.” Writing policies is the quick part. The hard part is the one that has to run every week: operating the controls and keeping the evidence — an evidence pack is how we help make that routine.

Where should you start?

Find out which report your customers actually ask for, then run a gap assessment against it before choosing dates. Scope and sequencing are the core of SOC 2 and ISO 27001 readiness, and the sales context is in security for SaaS selling to enterprise.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Who performs a SOC 2 examination?

Only a licensed CPA firm can perform a SOC 2 examination and sign the report. A readiness consultancy prepares you for it, and cannot be the firm that examines the same work.

Should we start with a Type 1 report?

Often, when a customer needs something soon. A Type 1 report covers the design of your controls at a point in time; it does not show they operated over a period, which is what a Type 2 report adds and what most enterprise buyers ask for in the end.

How long does SOC 2 take?

How long SOC 2 takes depends on where you start, how much you have to fix, and the observation period you agree with the CPA firm. Anyone quoting a duration before seeing your gaps is guessing; a gap assessment is what turns the question into a plan.

Does a compliance platform get us SOC 2?

No. A compliance platform can organize evidence and automate its collection, but it cannot operate your controls or examine them. The controls have to run, and a CPA firm has to test them.

How do you plan SOC 2 before setting dates?

Send the customer request and a short description of the system. The reply is a scope and a gap-assessment plan, with the decisions that set your timeline named. More of our writing is indexed at writing.

Discuss a scope